2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-25260
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 2 PoCs

Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

CVE-2023-3127
iSTAR Ultra General
7.5
HIGH
EPSS
0.2%
2023 CWE-287 1 PoC

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

CVE-2023-26130
yhirose/cpp-httplib Web
7.5
HIGH
EPSS
0.2%
2023 CWE-93 2 PoCs

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:** This issue is present due to an incomplete fix for [CVE-2020-11709](https://security.snyk.io/vuln/SNYK-UNMANAGED-YHIROSECPPHTTPLIB-2366507).

CVE-2023-26132
dottie General
7.5
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file.

CVE-2023-21931
WebLogic Server Database
7.5
HIGH
EPSS
83.8%
2023 4 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2023-4197
Dolibarr ERP CRM Web
7.5
HIGH
EPSS
51.1%
2023 CWE-20 2 PoCs

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

CVE-2023-38370
Security Access Manager Docker DevOps
7.5
HIGH
EPSS
0.0%
2023 CWE-276 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

CVE-2023-52285
Software Genérico Web Database
7.5
HIGH
EPSS
0.1%
2023 1 PoC

ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.

CVE-2023-26976
Software Genérico General
7.5
HIGH
EPSS
18.6%
2023 1 PoC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVE-2023-21850
Demantra Demand Management Web Database
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: E-Business Collections). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demantra Demand Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demantra Demand Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/

CVE-2023-30063
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.

CVE-2023-51810
Software Genérico Database
7.5
HIGH
EPSS
6.2%
2023 1 PoC

SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search parameter in the Users module.

CVE-2023-49298
Software Genérico General
7.5
HIGH
EPSS
0.7%
2023 1 PoC

OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related in realistic situations. A possible example is cp, from a recent GNU Core Utilities (coreutils) version, when attempting to preserve a rule set for denying unauthorized access. (One might use cp when configuring access control, such as with the /etc/hosts.deny file specified in t

CVE-2023-37474
copyparty General ⚡ nuclei
7.5
HIGH
EPSS
89.9%
2023 CWE-22 2 PoCs

Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-22047
PeopleSoft Enterprise PT PeopleTools Web Database ⚡ nuclei
7.5
HIGH
EPSS
91.6%
2023 2 PoCs

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2023-37608
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password.

CVE-2023-26111
@nubosoftware/node-static General
7.5
HIGH
EPSS
1.3%
2023 CWE-22 2 PoCs

All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.

CVE-2023-30699
Samsung Mobile Devices General
7.5
HIGH
EPSS
3.0%
2023 1 PoC

Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

CVE-2023-37029
Software Genérico Networking
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a compromised base station or via an unauthenticated cellphone within range of a base station managed by the MME, causing a denial of service.

CVE-2023-24498
ProSAFE 24 Port 10/100 FS726TP General
7.5
HIGH
EPSS
0.2%
2023 CWE-522 1 PoC

An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.